Collegeville, Pennsylvania · Serving Greater Philadelphia
Digital forensics for litigation and corporate investigations
4n6PI collects, preserves, and examines digital evidence for attorneys, corporate legal teams, and companies. Every matter is handled by the examiner who signs the report.
Evidence is not found. It is preserved, or it is lost.
A phone syncs overnight. Logs rotate. IT reimages the laptop before anyone thinks to ask. By the time a matter is filed, the record that would have answered the question is frequently gone already, and no amount of skill recovers what has been overwritten.
What survives is a matter of procedure. Devices are acquired write-blocked, so nothing on the original changes. Every image is hash-verified at acquisition and again at delivery, so the copy can be proven identical to the source. Custody is signed at the moment of handoff rather than reconstructed afterward, so the signature and the event share one clock. Each device is treated as its own record, and a finding from one is never carried to another.
The work is performed by certified examiners and documented so that another examiner, working independently from the same source, would reach the same result. That is the standard the rules of evidence rest on, and it is what separates a finding that holds from one that merely sounds right.
Reports state what the evidence supports, and say plainly where it stops.
Services
What 4n6PI does
For legal and litigation
Forensic Collection & Preservation
Defensible acquisition of computers, mobile devices, and removable media. Write-blocked imaging, hash verification, and chain of custody documented from intake through delivery.
Learn moreComputer Forensics
Examination of laptops, desktops, and servers. File access and transfer history, USB and cloud activity, deleted content, and reconstruction of what a user actually did and when.
Learn moreMobile Device Forensics
iOS and Android acquisition and analysis. Messages, call records, application data, location history, and deleted content, delivered in a form your team can review.
Learn moreIndependent Forensic Review
Review of forensic reports, extractions, and conclusions produced by another party. Whether the methodology was sound, and whether the source data actually supports what was claimed.
Learn moreeDiscovery & Forensic Collection
Microsoft 365, Purview, and cloud account collection. Legal hold administration, custodian collection, and export packaging formatted for your review platform.
Learn moreFor enterprise
Endpoint Investigations & Incident Response
Forensic investigation of compromised endpoints and active incidents. Triage, scope determination, timeline reconstruction, and reporting, working alongside your response lead.
Learn moreInsider Threat & Data Theft
Investigation of exfiltration, policy violation, and separation matters. What left, when it left, where it went, and what evidence supports each of those answers.
Learn moreEnCase Deployment & Recovery
Deploy, upgrade, troubleshoot, and recover EnCase Endpoint Investigator environments, including SAFE and node communication failures and post-upgrade recovery.
Learn moreMicrosoft Purview & Defender Support
Purview eDiscovery workflow, legal hold configuration, and Defender threat hunting inside your existing tenant. Built by someone who has stood the program up at enterprise scale.
Learn morePricing
Collection and analysis are priced separately
Most firms quote a single number that bundles acquisition and investigation together, so you commit to the analysis before anyone knows whether the matter needs it. 4n6PI separates the two.
| Service | Rate | What it covers |
|---|---|---|
| Mobile device acquisition and processing | $2,500 | Flat, per single device |
| Hard drive imaging | $1,500 | Flat, per single drive |
| Investigation and analysis | $150/hr | Only when the matter calls for it |
| Storage media | At cost | No markup |
What the flat rate includes
Forensic acquisition, hash verification, chain of custody documentation, and output formatted for review. You can take that output and search it yourself, or engage 4n6PI to perform the investigation at the hourly rate. Where a matter needs one, a review platform is provided.
Multi-device matters are quoted per engagement. Travel and on-site work is billed at cost with advance written authorization.
Location
Based in Montgomery County, not a landing page
4n6PI works out of Collegeville, Pennsylvania. Devices are collected in person across Norristown, King of Prussia, Lansdale, Blue Bell, Pottstown, Philadelphia, and the surrounding counties, which means evidence can be in hand the same day rather than in transit.
Remote collection and evidence intake coordination are available nationwide when a matter requires it.
Start a matter
Whether you have a device in hand, a preservation obligation, or a report from the other side that needs a second look, the first conversation is free and takes about thirty minutes.